February 2026 vulnerability: What happened?
Blog post from Metabase
A vulnerability in Metabase's notification API, discovered by security researcher Sho Odagiri, allowed authenticated users to create notification templates that could extract and email database connection details, including credentials. The issue arose from the introduction of Handlebars templates for email content and metadata objects in query results, which were not adequately restricted, allowing access to sensitive information. Metabase addressed this by locking down the Handlebars template engine and removing method resolvers that enabled arbitrary Java method invocations, as well as stripping metadata from query results. All Metabase Cloud instances have been updated to eliminate the vulnerability, and self-hosted users are urged to upgrade to specific versions or newer. To prevent future risks, Metabase is enhancing logging and securing credential access paths. There is no evidence that the vulnerability was exploited before the fix, and credit is given to Sho Odagiri for the discovery.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.